Solaris 11 SPARC Security Technical Implementation Guide
Rules, Groups, and Values defined within the XCCDF Benchmark
-
The centralized process core dump data directory must be owned by root.
<VulnDiscussion>Process core dumps contain the memory in use by the process when it crashed. Any data the process was handling may be contain...Rule Medium Severity -
SRG-OS-000480
<GroupDescription></GroupDescription>Group -
The centralized process core dump data directory must be group-owned by root, bin, or sys.
<VulnDiscussion>Process core dumps contain the memory in use by the process when it crashed. Any data the process was handling may be contain...Rule Medium Severity -
SRG-OS-000480
<GroupDescription></GroupDescription>Group -
The centralized process core dump data directory must have mode 0700 or less permissive.
<VulnDiscussion>Process core dumps contain the memory in use by the process when it crashed. Any data the process was handling may be contain...Rule Medium Severity -
SRG-OS-000480
<GroupDescription></GroupDescription>Group -
Kernel core dumps must be disabled unless needed.
<VulnDiscussion>Kernel core dumps may contain the full contents of system memory at the time of the crash. Kernel core dumps may consume a co...Rule Medium Severity -
SRG-OS-000480
<GroupDescription></GroupDescription>Group -
The kernel core dump data directory must be owned by root.
<VulnDiscussion>Kernel core dumps may contain the full contents of system memory at the time of the crash. As the system memory may contain s...Rule Medium Severity -
SRG-OS-000480
<GroupDescription></GroupDescription>Group -
The kernel core dump data directory must be group-owned by root.
<VulnDiscussion>Kernel core dumps may contain the full contents of system memory at the time of the crash. As the system memory may contain s...Rule Medium Severity -
SRG-OS-000480
<GroupDescription></GroupDescription>Group -
The kernel core dump data directory must have mode 0700 or less permissive.
<VulnDiscussion>Kernel core dumps may contain the full contents of system memory at the time of the crash. As the system memory may contain s...Rule Medium Severity -
SRG-OS-000480
<GroupDescription></GroupDescription>Group -
The system must require passwords to change the boot device settings. (SPARC)
<VulnDiscussion>Setting the EEPROM password helps prevent attackers who gain physical access to the system console from booting from an exter...Rule Low Severity -
SRG-OS-000480
<GroupDescription></GroupDescription>Group -
The operating system must implement transaction recovery for transaction-based systems.
<VulnDiscussion>Recovery and reconstitution constitutes executing an operating system contingency plan comprised of activities to restore ess...Rule Medium Severity -
SRG-OS-000480
<GroupDescription></GroupDescription>Group -
SNMP communities, users, and passphrases must be changed from the default.
<VulnDiscussion>Whether active or not, default SNMP passwords, users, and passphrases must be changed to maintain security. If the service is...Rule High Severity -
SRG-OS-000480
<GroupDescription></GroupDescription>Group
Node 2
The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.